A critical vulnerability (CVE-2026-19977) has been identified in EFM ipTIME A3004T firmware version 14.19.0. The flaw resides in the `httpcon_check_session_url` function within the Session Validation component, which fails to properly authenticate requests. This allows remote attackers to bypass authentication mechanisms and execute unauthorized actions. The vulnerability is actively exploited via publicly available exploits, posing a severe risk to affected systems. The vendor was notified but has not released a patch or acknowledgment. Organizations deploying the EFM ipTIME A3004T appliance are strongly advised to implement immediate mitigations, such as restricting network access to trusted sources or applying custom workarounds to enforce session validation. Given the public exploit availability and high CVSS score (10.0), urgent action is required to prevent potential compromise.